11 remotely exploitable vulnerabilities in the TCP/IP stack of VxWorks

Security researchers from Armis revealed information about 11 vulnerabilities (PDF) in the TCP/IP stack IPnet, used in the VxWorks operating system. The issues have been assigned the code name "URGENT/11". These vulnerabilities can be exploited remotely by sending specially crafted network packets. For some issues, it is possible to carry out attacks even through firewalls and NAT (for example, if the attacker controls the DNS server that the vulnerable device on the internal network queries).

11 remotely exploitable vulnerabilities in the TCP/IP stack of VxWorks

Six issues could lead to remote code execution when handling improperly set IP or TCP options in packets, as well as when parsing DHCP packets. Five issues are less severe and may lead to information leakage or DoS attacks. Information about the vulnerabilities has been coordinated with Wind River — in the last release of VxWorks 7 SR0620 published last week, the issues have already been addressed.

Since each vulnerability affects different parts of the network stack, the issues may be specific to certain releases, but it is claimed that at least one vulnerability allowing for remote code execution exists in every version of VxWorks since 6.5. Moreover, a separate exploit must be created for each version of VxWorks. According to Armis, the issue affects approximately 200 million devices, including industrial and medical equipment, routers, VOIP phones, firewalls, printers, and various Internet of Things devices.

Wind River believes, that this number is exaggerated and that the issue only affects a relatively small number of non-critical devices, which are usually limited to internal corporate networks. The IPnet stack was only supplied with certain editions of VxWorks, including releases that are no longer supported (up to 6.5). The devices based on the VxWorks 653 and VxWorks Cert Edition platforms, used in critical areas (industrial robots, automotive, and aerospace electronics), do not exhibit these issues.

Armis representatives believe that due to the complexity of updating vulnerable devices, the emergence of worms that affect local networks and attack the most popular categories of vulnerable devices en masse is not out of the question. For example, some devices, such as medical and industrial equipment, require re-certification and lengthy testing during firmware updates, which complicates the process of updating their firmware.

Wind River believes, in such cases the risk of compromise can be reduced by enabling existing built-in security measures, such as non-executable stack, stack overflow protection, system call limitations, and process isolation. Protection can also be provided by adding attack-blocking signatures on firewalls and intrusion prevention systems, as well as restricting network access to the device to only the internal security perimeter.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster